Financial crime

Anti-money laundering

How GBF Payment Services prevents money laundering, terrorist financing, sanctions evasion and proliferation financing across the United States, the United Kingdom, the European Union and every other market we serve.

Last updated 29 August 2026 — Draft for legal review. Jurisdiction-specific wording to be confirmed with local counsel before publication.

Purpose and scope

This policy sets out the controls GBF Payment Services applies to prevent, detect and report money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud and other financial crime. It applies to every customer, every account, every payment instruction and every member of staff and contractor, in every market where we operate.

GBF Payment Services delivers regulated payment activity country by country through locally licensed payment partners. Where a local partner holds the licence, that partner's programme applies in addition to this policy. Where the two differ, the stricter control applies. Nothing in this policy reduces an obligation imposed by applicable law.

The policy is written to satisfy, at minimum, the following frameworks:

  • United States — the federal anti-money laundering statute at 31 USC 5311 and following, as amended by the USA PATRIOT Act and the Anti-Money Laundering Act of 2020, together with the implementing regulations at 31 CFR Chapter X, the Financial Crimes Enforcement Network's rules for money services businesses, and the sanctions programmes administered by the Office of Foreign Assets Control.
  • United Kingdom — the Proceeds of Crime Act 2002, the Terrorism Act 2000, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 as amended, the Sanctions and Anti-Money Laundering Act 2018, and Financial Conduct Authority rules and guidance including the Joint Money Laundering Steering Group guidance.
  • European Union — the Fourth, Fifth and Sixth Anti-Money Laundering Directives as transposed in each member state, Regulation (EU) 2015/847 on information accompanying transfers of funds, the EU Anti-Money Laundering Regulation and the Sixth Directive package establishing the Anti-Money Laundering Authority, and applicable guidelines issued by the European supervisory authorities.
  • Global — the Financial Action Task Force Forty Recommendations, United Nations Security Council sanctions resolutions, and the standards of each regional FATF-style body covering the markets we serve.

Governance and accountability

Accountability for the financial crime programme sits with the board. The board approves this policy at least annually and receives quarterly reporting on control performance, case volumes, escalations and remediation.

Day-to-day ownership rests with the Money Laundering Reporting Officer, a named individual with sufficient seniority, independence and resource to act without commercial pressure. In the United Kingdom the role also discharges the nominated officer function under the Proceeds of Crime Act 2002. In the United States the equivalent role is the designated compliance officer required by 31 CFR 1022.210. In European Union markets a compliance officer at management level and a designated board member are appointed where local transposition requires it.

The programme is organised in three lines:

  • First line — product, operations and support teams that apply controls in the course of their work and escalate concerns immediately.
  • Second line — the compliance function, which owns policy, risk assessment, calibration of monitoring rules, sanctions decisioning, regulatory reporting and training.
  • Third line — independent audit, which tests design and operating effectiveness on a risk-based cycle and reports findings directly to the board.

An independent review of the programme is commissioned at least every twenty-four months, and sooner following material change to the business, the customer base or the regulatory framework.

Business-wide risk assessment

We maintain a documented business-wide risk assessment that is reviewed at least annually and whenever a material change occurs — a new market, a new payment corridor, a new partner, a new product feature, or a change in the threat picture.

The assessment scores inherent risk, control effectiveness and residual risk across five dimensions:

  • Customer risk — customer type, occupation or sector, ownership structure, exposure to politically exposed persons, adverse media and prior conduct.
  • Country and geographic risk — country of residence, incorporation, tax presence, and the origin and destination of funds, assessed against FATF listings, EU high-risk third-country lists, UK High Risk Third Countries, and credible corruption and governance indices.
  • Product and service risk — the specific capability used, including multi-currency positions, incoming payments, outbound transfers, peer-to-peer payments and currency conversion.
  • Channel risk — remote onboarding, device binding, and the strength of identity evidence available in each market.
  • Transaction risk — value, velocity, structuring indicators, counterparty concentration and corridor characteristics.

Risk scores drive the level of due diligence applied, the monitoring thresholds set, and the frequency of periodic review.

Customer due diligence

No customer may move funds outbound until identity verification is complete and approved. Due diligence is applied at onboarding, on trigger events, and on a periodic cycle set by risk rating.

Standard due diligence establishes and verifies identity from independent, reliable sources. For an individual this covers full legal name, date of birth, residential address, nationality and a government-issued identity document validated for authenticity and expiry, supported by a liveness check. For an organisation it covers legal name, registered number, registered and trading address, legal form, constitutional documents, the identity of directors and senior managing officials, and the identity of every beneficial owner.

Simplified due diligence is applied only where the law of the relevant market expressly permits it and the documented risk assessment supports it. It is never applied to a customer in a high-risk category and never removes monitoring.

Enhanced due diligence is mandatory for politically exposed persons, their family members and close associates; customers connected to a high-risk third country; complex or unusual ownership structures; unusually large or structurally unexplained activity; and any relationship where a screening alert or adverse media finding is not fully resolved. Enhanced measures include senior management approval to open or continue the relationship, establishing the source of funds and, where relevant, the source of wealth, and increased frequency of review.

Ongoing due diligence keeps records current. High-risk relationships are reviewed at least annually, medium-risk at least every two years and low-risk at least every three years, and immediately on a trigger event such as a change of control, a change of country, a sanctions match or a suspicious activity report.

Where verification cannot be completed to the required standard, the relationship is not opened, or is restricted or exited, and the circumstances are considered for reporting.

Sanctions, export controls and prohibited activity

Screening runs against consolidated lists including those maintained by the Office of Foreign Assets Control, the United Kingdom Office of Financial Sanctions Implementation, the European Union consolidated list, United Nations Security Council lists and applicable local lists for each market served.

Screening is applied to every customer, every beneficial owner, every controller and every counterparty at onboarding, on every list update and before every outbound instruction is released. Payment messages are screened against name, country and free-text fields.

A potential match suspends the action pending review. A confirmed match results in the payment being stopped, the position restricted, the matter reported to the competent authority, and the funds blocked or rejected as the applicable regime requires. We do not tip off a customer as to the existence or content of a sanctions investigation or a suspicious activity report; the customer sees only that the action is restricted, together with a reference identifier for support.

We do not knowingly facilitate activity in or for the benefit of a comprehensively sanctioned jurisdiction, nor activity that would breach applicable export control or anti-boycott rules. We do not support anonymous accounts, accounts in fictitious names, payable-through arrangements, shell entities without demonstrable economic purpose, unlicensed money transmission, unlicensed gambling, the sale of controlled weapons, or the trade in illicit goods, materials or wildlife.

Transaction monitoring

Activity is monitored on a risk-based, rules-and-behaviour basis. Monitoring covers incoming and outgoing payments, currency conversion, peer-to-peer activity, counterparty patterns and account behaviour, and combines deterministic rules with profile deviation.

Typologies covered include structuring beneath reporting or verification thresholds, rapid pass-through of funds with no economic rationale, fan-in and fan-out patterns, mismatch between stated purpose and observed activity, unexpected exposure to high-risk corridors, mule indicators such as coordinated device or address reuse, and behaviour consistent with authorised push payment fraud or romance and investment fraud.

Alerts are queued, worked to a documented service level and dispositioned with reasons recorded. Rules are tuned at least twice a year with model performance evidence retained, and every tuning change is version-controlled and approved by the second line.

Payment messages carry the payer and payee information required by the Transfer of Funds Regulation, the equivalent United Kingdom regulation and the Financial Crimes Enforcement Network travel rule. Instructions arriving with incomplete information are held, queried or rejected.

Internal escalation and regulatory reporting

Any member of staff who knows, suspects or has reasonable grounds to suspect financial crime must escalate internally to the Money Laundering Reporting Officer without delay and without discussing the matter with the customer. Internal reports are acknowledged, investigated and documented, whether or not they result in an external filing.

Where the threshold is met, the Money Laundering Reporting Officer files with the competent authority in the relevant jurisdiction — the Financial Crimes Enforcement Network in the United States, the National Crime Agency in the United Kingdom, and the designated financial intelligence unit in each European Union member state or other market. Threshold-based reporting, including currency transaction reporting in the United States, is filed where applicable.

Where a defence against a money laundering offence is required before an instruction can proceed, the instruction is held until consent is granted or the statutory notice period expires. Tipping off is a criminal offence and is prohibited absolutely.

Record keeping and data retention

We retain identity evidence, verification results, due diligence records, screening decisions, monitoring alerts, investigation notes, internal escalations, regulatory filings and payment records for at least five years from the end of the customer relationship or the date of the transaction, and for longer where local law, a regulator or a lawful order requires it.

Records are held in a form that permits reconstruction of an individual transaction and prompt response to a lawful request. Retention is balanced against data protection obligations: records are deleted or anonymised once every applicable retention period has expired. The Privacy notice explains how personal data is handled, and financial crime retention is one of the lawful bases described there.

Training, screening of staff and culture

Every member of staff completes financial crime training at induction and at least annually, with role-specific modules for teams handling onboarding, payment operations, support and engineering. Training covers typologies relevant to the markets served, escalation duties, tipping-off restrictions, sanctions obligations and personal criminal liability. Completion is recorded and non-completion is escalated.

Staff in roles with financial crime responsibility are screened before appointment and re-screened periodically, to the extent local employment law permits. Staff may raise concerns confidentially through a protected whistleblowing channel that reports to the board without management filtering, and retaliation against a person raising a concern in good faith is a disciplinary matter.

Partners, outsourcing and correspondent relationships

Payment capability is delivered through licensed partners selected after due diligence covering licensing status, ownership, financial standing, control environment, regulatory history and sanctions exposure. Contracts require compliance with applicable financial crime law, audit and information rights, incident notification, and a right to terminate for control failure.

Partner performance is monitored, with periodic reassessment at a frequency set by risk. Outsourcing never transfers accountability: where a function is performed by a third party, GBF Payment Services remains responsible for the outcome. Partner identity is treated as confidential operational information and is not displayed as a product field.

Contact and requests from authorities

Law enforcement, regulators and financial intelligence units may contact the compliance function through the details on our Contact page. Requests are validated for legal authority before any information is released, and each request is logged.

Customers with a question about a restricted action should contact support with the reference identifier shown on screen. We cannot confirm or deny the existence of a financial crime investigation, and support cannot lift a restriction that arises from one.